• Security hole in kernel fixed?

    From Hans@21:1/5 to All on Wed May 15 09:10:01 2024
    This is a multi-part message in MIME format.

    Dear developers,


    in April 2024 the security hole CVE-2023-6546 was discovered in linux-image, and I believe, it
    is fixed in kernel 6.1.0 (from debian/stable) as soon after this a new kernel was released.


    However, there is no new kernel 6.5.0-*-bpo released at that time, so my question:


    Does anyone know, if this fix was also integrated in kernel 6.5.0-*.bpo ?

    Thanks for your answer.

    Best

    Hans





    <html>
    <head>
    <meta http-equiv="content-type" content="text/html; charset=UTF-8">
    </head>
    <body><p style="margin-top:0;margin-bottom:0;margin-left:0;margin-right:0;">Dear developers,</p>
    <p style="margin-top:0;margin-bottom:0;margin-left:0;margin-right:0;"><br /></p>
    <p style="margin-top:0;margin-bottom:0;margin-left:0;margin-right:0;">in April 2024 the security hole <span style="font-family:Hack;">CVE-2023-6546 was discovered in linux-image, and I believe, it is fixed in kernel 6.1.0 (from debian/stable) as soon
    after this a new kernel was released.</span></p>
    <p style="margin-top:0;margin-bottom:0;margin-left:0;margin-right:0;"><br /></p>
    <p style="margin-top:0;margin-bottom:0;margin-left:0;margin-right:0;">However, there is no new kernel 6.5.0-*-bpo released at that time, so my question: </p>
    <p style="margin-top:0;margin-bottom:0;margin-left:0;margin-right:0;"><br /><br />Does anyone know, if this fix was also integrated in kernel 6.5.0-*.bpo ?</p>
    <br /><p style="margin-top:0;margin-bottom:0;margin-left:0;margin-right:0;">Thanks for your answer.</p>
    <br /><p style="margin-top:0;margin-bottom:0;margin-left:0;margin-right:0;">Best</p>
    <br /><p style="margin-top:0;margin-bottom:0;margin-left:0;margin-right:0;">Hans</p>
    <p>&nbsp;<p>&nbsp;<p>&nbsp;</p>
    </body>
    </html>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From The Wanderer@21:1/5 to Hans on Wed May 15 13:10:01 2024
    This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
    On 2024-05-15 at 03:05, Hans wrote:

    Dear developers,

    As usual, most of us here are not Debian developers, even if some of us
    may be software developers.

    in April 2024 the security hole CVE-2023-6546 was discovered in linux-image, and I believe, it
    is fixed in kernel 6.1.0 (from debian/stable) as soon after this a new kernel was released.

    However, there is no new kernel 6.5.0-*-bpo released at that time, so my question:

    Does anyone know, if this fix was also integrated in kernel 6.5.0-*.bpo ?

    I don't have a definitive answer, but you might look at:

    https://security-tracker.debian.org/tracker/CVE-2023-6546

    The only place it mentions 6.5 is in the Notes section, where it
    mentions 6.5-rc7 (with a kernel.org link) in the context of a statement
    that the Linux kernel in Debian buster does not include the vulnerable
    code.

    I would therefore suspect that any 6.5.x kernel probably was not
    affected by this vulnerability to begin with.

    --
    The Wanderer

    The reasonable man adapts himself to the world; the unreasonable one
    persists in trying to adapt the world to himself. Therefore all
    progress depends on the unreasonable man. -- George Bernard Shaw


    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEJCOqsZEc2qVC44pUBKk1jTQoMmsFAmZEly8ACgkQBKk1jTQo MmsP+w/9H9+hwKjrB9QHNmM9OFR6y4G7BYVbChDcp0karwySyvKdtvJNASPmlSKq /ykbFVZaQw6pLPDnPvB4on07oiWjaOjb0X+jO8IDcoCb2au40rQ5ZgJacalIe/1m qv7h/qOjqty1egfT4n/1Be6yhGHTGXvV92oSgboXsPLwKzoXQbdxjXSLBBzmuJH/ SAwG6QNTpz3Rxe6QBX9kyYdkN16umzwNJrQFLd4atcHgT56Add+GQP3mB3imKE9O FvncqIeB+pimIJs/DUBmQCcdLMcvP0Mhwimyi7Z6PweLjcbU/Al5XTF4YAJ76Dow n3IsgidbLinLg2JCdnBLKAIRVISKKsRMnjcv6VtaLeKOnFnf3GfK3Q6mHiaYbO5j QO9Fk8af4LLz+r6CHl4H1kwqcq7eJQDg1/wUa/xmTfDoYIhdv3bz3pF81LixgpV/ NQzBWKShg/4wUP0cRvQJiQnKYLkJ7NatJ2Jk1pSQgF/zqVUVGdCUwXjjObuyk+/H NEp49MxQR4Np/rBQIulERVdWpE4l/lS4IGG+kkjWkjP/tdcXE2E9pY3mP7mEVP1a hFRqaaHYOhfadJdvvnxErkVmvTKsm1/6Izn4rUqFWikyX9oLk0Scnh7gnexDUoX5 9FLe6OxY2qXmIpNUTtxF55/Yn/tO